Healthcare technology firm CareCloud has disclosed a significant data breach, affecting the personal information of over 350,000 individuals. The breach occurred within its electronic health record system, part of the CareCloud Health division, on March 16, 2026.
Details of the Security Breach
The breach, confirmed through an internal investigation, revealed unauthorized access to one of CareCloud’s AWS environments, occurring between March 10 and March 16. During this time, cybercriminals likely extracted sensitive data from the system.
On June 24, CareCloud concluded that the attack compromised various types of personal and financial data. Affected information includes names, addresses, Social Security numbers, and other sensitive identifiers. The notification was sent to individuals who may have been impacted, with a copy also filed with the Massachusetts Office of Consumer Affairs and Business Regulation.
Impact on Affected Individuals
The breach has led to the exposure of sensitive data for a substantial number of people. CareCloud estimates that at least 350,000 individuals have had their information accessed. To mitigate the potential impact, the company offers up to 24 months of free identity theft protection, credit monitoring, and recovery services, which are backed by a $1,000,000 insurance reimbursement policy.
Despite these measures, the full scope of the breach remains unclear, as CareCloud has not disclosed the total number of affected individuals or the identity of the attackers involved.
Ongoing Security Measures
In response to the incident, CareCloud has engaged external cybersecurity experts to secure the compromised environment and prevent further unauthorized access. The company reports that no ongoing threats exist and continues to enhance the security of its systems.
CareCloud has not yet released additional details regarding the breach. SecurityWeek has reached out for more information and will provide updates as they become available.
This breach highlights the ongoing challenges faced by organizations in securing sensitive healthcare data against sophisticated cyber threats.
